SUSPICIOUS — 604bd7d5310b2.pdf
SUSPICIOUS — 604bd7d5310b2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
bcc91871b3fb453ed4ab6cdaade2891736cb147aac01b656aeae0e0b74f02e5c - SHA-1:
91cdfc7626e6049a960e4ef5861aa55cc2a5540f - MD5:
ef8e9a346e3bbdcc3eebd01f26702234 - ssdeep:
1536:MGF1edf9nwZ+71GfO8hzSWMikYuCbjgnHZbW:pF1edf1i+ZQKZ37CbjIw - TLSH:
T12C349EF310ABED4DBB8BAB43AAE71198614AD3886132936044CC773CD47C6ED6F11964 - Submitted as: 604bd7d5310b2.pdf
- File type: pdf · Size: 55914 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=vice%20city%20pc%20download%20full%20version, https://cdn-cms.f-static.net/uploads/4366407/normal_5f87288fefdf2.pdf, https://cdn-cms.f-static.net/uploads/4369923/normal_5f8ad3e494b48.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=vice%20city%20pc%20download%20full%20version
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f87288fefdf2.pdf
- https://cdn-cms.f-static.net/uploads/4369923/normal_5f8ad3e494b48.pdf
- https://cdn-cms.f-static.net/uploads/4369782/normal_5f88192f3d272.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f871e67e5745.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870cc9492b5.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f877b2cf38b5.pdf
- https://cdn-cms.f-static.net/uploads/4377925/normal_5f8c0c2419891.pdf
- https://cdn.shopify.com/s/files/1/0488/3759/1205/files/iaf_a_cut_above_game_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0505/2701/0988/files/neonatal_intracranial_hemorrhage.pdf
- https://uploads.strikinglycdn.com/files/8b7cb3b3-5bd1-4b74-bbb0-688a34ed03ea/spirit_list_smash_ultimate.pdf
- https://uploads.strikinglycdn.com/files/e3bad227-83a9-4e41-8a6e-248272e3474d/backuptrans_android_iphone_line_transfer_crack.pdf
- https://uploads.strikinglycdn.com/files/1b293485-c0a6-49e9-ba41-6bc7243e0667/xforce_keygen_photoshop_cs2.pdf
- https://uploads.strikinglycdn.com/files/37b73b89-224d-4ff8-a55c-6ad85e283dcc/liginituzona.pdf
- https://uploads.strikinglycdn.com/files/022eb8d3-1836-4a00-9b31-272da496428f/24507619458.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f886d5f2b278.pdf
- https://cdn-cms.f-static.net/uploads/4380084/normal_5f8f5975b1d14.pdf
- https://cdn-cms.f-static.net/uploads/4370778/normal_5f895da7dcbd0.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f8761663a9a5.pdf
- https://cdn-cms.f-static.net/uploads/4373782/normal_5f8c32ac22c46.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/bupexusarusal.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/barajeri-saxutorukaxa-wefixufinib.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- dejolezeg.weebly.com
- digonowokeke.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report